---
cve: "CVE-2023-36556"
severity: "HIGH"
cvss: 8.6
epss: "84%"
vendor: "Fortinet"
kev: false
exploited: false
published: "2023-10-10 17:15:12"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T19:44:57+02:00"
---

# CVE-2023-36556

> 8.6 HIGH

## Beschreibung

An incorrect authorization vulnerability [CWE-863] in FortiMail webmail version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.5 and below 6.4.7 allows an authenticated attacker to login on other users accounts from the same web domain via crafted HTTP or HTTPs requests.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:X/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Schwachstellen-Klasse

- **CWE-863** — Incorrect Authorization
  The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

## Referenzen

- <https://fortiguard.com/psirt/FG-IR-23-202>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2023-36556) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
